CVE-2024-36464: Media Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exported
When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36464?
The severity of CVE-2024-36464 is considered low as it primarily involves best practices around password visibility in YAML exports.
How do I fix CVE-2024-36464?
To fix CVE-2024-36464, ensure that proper access controls are enforced and consider encrypting sensitive data before export.
What versions of Zabbix are affected by CVE-2024-36464?
CVE-2024-36464 affects Zabbix versions from 6.0.0 to 6.0.30 and from 6.4.0 to 6.4.15.
What is the impact of CVE-2024-36464?
The impact of CVE-2024-36464 is that passwords may be exposed in plain text if exported, but only users with permissions can access this information.
Is CVE-2024-36464 a significant vulnerability?
CVE-2024-36464 is not considered a significant vulnerability due to its low impact on security when appropriate access controls are in place.